vulnerability
WordPress Plugin: wp-reset: CVE-2021-36909: Improper Access Control
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:S/C:N/I:P/A:P) | Nov 10, 2021 | May 15, 2025 | Jul 10, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:P)
Published
Nov 10, 2021
Added
May 15, 2025
Modified
Jul 10, 2025
Description
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions less than or equal to 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.
Solution
wp-reset-plugin-cve-2021-36909
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.